All articles

Two R5 million POPIA fines have been issued — and in every case so far, the fine followed a warning that was ignored

The breach was never the trigger. Failing to fix it after the Regulator said so was.

Has Anyone Actually Been Fined Under POPIA? Here’s What’s Happened So Far

7 August 20267 min read·Compliance intelligence

If you have ever wondered whether the Protection of Personal Information Act (POPIA) — South Africa’s data privacy law — actually gets enforced, the short answer is yes. It is no longer a law with penalties on paper and nothing behind them. South Africa’s Information Regulator, the body that enforces POPIA, has issued real fines, and it has warned publicly that more are coming.

Here is what has actually happened, in plain terms — and what it means if you run a business with a website that collects any personal information (which, if you have a contact form, a newsletter sign-up, or an online store, means you).

The first POPIA fine: R5 million

In 2023, the Information Regulator issued its first-ever administrative fine under POPIA — R5 million against the Department of Justice and Constitutional Development. It followed a 2021 ransomware attack that exposed personal information from over a thousand files.

Here is the part that matters most for any business owner: the fine was not for getting hacked. It was for what happened after. The department had let its security software licences lapse — including the tool that would have flagged the unauthorised access in the first place. The Regulator issued an enforcement notice ordering the department to fix its security and prove it. When that did not happen, the fine followed.

In other words: the breach was not the crime. Ignoring the warning was.

The second fine: another R5 million

In December 2024, the Regulator issued a second R5 million fine — this time against the Department of Basic Education, for publishing matric results without consent.

Smaller penalties have followed too. A pathology business was fined for failing to report a data breach when it happened — another case of the cover-up, not the incident itself, triggering the enforcement action.

It is not just fines — WhatsApp got an enforcement notice too

In April 2025, the Regulator issued a formal enforcement notice against WhatsApp, after finding that South African users were given weaker privacy protections than users in Europe — a breach of POPIA’s accountability and purpose specification requirements. It shows the Regulator is willing to take on large, well-resourced companies, not just government departments.

The trend: enforcement is accelerating

A few numbers worth knowing:

  • Data breach notifications rose more than 40% year-on-year in the 2024–2025 reporting period, with over 2,000 reported.
  • The maximum administrative fine under POPIA is R10 million — the fines issued so far are exactly half that.
  • The Information Regulator’s own spokesperson has said publicly that more fines are coming.

The pattern across every case so far is consistent: a security or privacy failure happens, the Regulator flags it, and the fine only lands if the organisation does not fix it. Businesses that respond to a compliance gap tend to avoid the fine. Businesses that ignore it do not.

Why this matters even if you are a small business

Every case above involved a large organisation — government departments, a pathology group, a multinational tech company. It is easy to assume POPIA enforcement is a big-business problem. But POPIA applies to every business that collects personal information from South Africans, regardless of size — and a huge share of that collection happens through something every business has: a website.

A contact form that stores names and email addresses. A newsletter sign-up. An online booking system. Even Google Analytics running in the background. All of it falls under POPIA. And most South African SME websites were never built with POPIA in mind — because for most of them, it simply was not on the radar when the site was made.

The Regulator has said clearly that its enforcement approach follows a pattern: identify the gap, notify the business, then act if nothing changes. The businesses at real risk are not the ones with a gap — almost everyone has one somewhere. It is the ones who do not know the gap exists, and so never get the chance to close it before it becomes a problem.

What a compliant website actually needs

At a minimum, POPIA expects your website to have:

  • A privacy notice — telling visitors what personal information you collect and why
  • A PAIA manual — a legally required document under the Promotion of Access to Information Act, explaining how someone can request access to information you hold
  • Information Officer details — a named person visitors can contact about their data
  • Clear data subject rights — a way for people to ask what you hold on them, correct it, or have it deleted
  • Secure forms — any form collecting personal information needs appropriate safeguards
  • Disclosed tracking scripts — if you are running analytics, ad pixels, or similar tools, visitors need to know

Most SME sites are missing at least one or two of these — not out of negligence, but because nobody flagged it. When we scanned 4,221 South African business websites, 95% published no Information Officer contact and 91% had no PAIA manual.

Check where your website stands

We built a tool that scans any South African business website against these exact POPIA essentials, in under a minute. The check is free and needs no sign-up: you get your score, every one of the eight checks marked pass or fail, and one finding spelled out in full. The complete report — every finding, the steps to fix each one, and the documents you are missing as editable Word files — is R19 once-off if you want it.

Run your free POPIA website check →

It is not a legal audit or a certification — for that, you would need a qualified attorney or POPIA specialist. But it is a fast, honest first look at whether your site has the basics in place, before a compliance gap becomes something bigger.

If the check flags a missing Information Officer, that one is free to fix and takes under 30 minutes — see our guide to registering an Information Officer.


Sources: Information Regulator of South Africa — enforcement notices and media statements on the Department of Justice and Constitutional Development (2023) and Department of Basic Education (December 2024) administrative fines; enforcement notice issued to WhatsApp (April 2025); Information Regulator annual report data on security compromise notifications, 2024–2025. POPIA sections 19, 22 and 109 (administrative fines).

ClearComply is a private commercial software provider and is not affiliated with, authorized by, or an official agency of CIPC or any government entity. We are not the Information Regulator. Our website check is an automated scan of what a site publishes — it is not a legal audit, a certification, or a finding by any regulator.

ClearComply

All your compliance, tracked in one place

Check your status, follow a step-by-step fix, and track every CIPC, SARS, UIF, COIDA, B-BBEE and POPIA deadline from one dashboard — with automatic reminders before each one. Check, fix, comply, track — from R99/month.

Behind on COIDA? Get expert COIDA help →·Filing CIPC yourself? Try the Co-Pilot →

Got questions?

Pick a question or type your own below.